Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-32691

Опубликовано: 18 мар. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 5.3

Описание

A race condition in the secrets management subsystem of Juju versions 3.0.0 through 3.6.18 allows an authenticated unit agent to claim ownership of a newly initialized secret. Between generating a Juju Secret ID and creating the secret's first revision, an attacker authenticated as another unit agent can claim ownership of a known secret. This leads to the attacking unit being able to read the content of the initial secret revision.

РелизСтатусПримечание
devel

DNE

jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

snap

needs-triage

upstream

needs-triage

Показывать по

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
5 месяцев назад

A race condition in the secrets management subsystem of Juju versions 3.0.0 through 3.6.18 allows an authenticated unit agent to claim ownership of a newly initialized secret. Between generating a Juju Secret ID and creating the secret's first revision, an attacker authenticated as another unit agent can claim ownership of a known secret. This leads to the attacking unit being able to read the content of the initial secret revision.

CVSS3: 5.3
debian
5 месяцев назад

A race condition in the secrets management subsystem of Juju versions ...

CVSS3: 5.3
github
5 месяцев назад

Juju affected by timing ownership claim attack on new external back-end secrets

5.3 Medium

CVSS3